Custodis markCustodis
LEGAL

Privacy Policy

LAST UPDATED · 10 JUNE 2026

1. What we collect

We collect what we need to run the service and nothing we cannot justify. Account information includes your email, name, a hashed password, and an optional passkey credential. Organization information includes the organization name, an industry sector drawn from a fixed taxonomy, and a billing email. Scan data covers the domains you register, hostnames discovered through certificate transparency logs, and the findings and evidence we capture during scans (response headers, banner output, certificate chains, DNS records). Usage telemetry covers sign-in events, IP addresses for the audit log, and entries written by your actions inside the console. We do not collect biometric data, location data, or device fingerprints beyond what is strictly necessary for session security.

2. How we use it

We use your data to operate the service: running scheduled and ad-hoc scans, computing and recomputing scores, and dispatching alerts to the channels you have configured. We use billing data to charge the correct amount and send invoices. We use request metadata to secure the platform — rate-limiting, abuse detection, and the immutable audit log. We use aggregated, de-identified metrics to improve the product; we never inspect or learn from any single tenant's individual data. We use the email address on file to respond to support requests you initiate. Every other use requires your explicit consent in writing.

3. What we do not do

We do not sell your data. We do not share your data with data brokers, advertising networks, or any third party not listed as a sub-processor in section 5. We do not train machine-learning models on your tenant data — not for our products, not for our partners, not for anyone. We do not share scan evidence with any third party, including researchers, regulators, or other Custodis customers, without a lawful order or your written instruction. We do not use your data for any purpose outside the operational ones described above.

4. Where it lives

Tenant data is hosted in the EU or US depending on your organization's region setting, chosen at sign-up. All data is encrypted in transit using TLS 1.2 or newer and at rest using AES-256. Encrypted backups are retained for thirty days and then irreversibly destroyed. Every administrative access to the production database is recorded in a separate, append-only access log that is reviewed weekly. We segregate tenant data at the row level with enforced policies; cross-tenant queries by employees require a documented support ticket and reviewer approval.

5. Sub-processors

We rely on a small set of sub-processors to deliver the service: Stripe for billing and payment processing, Resend for transactional email (sign-in, alerts, invoices), a hosting provider for compute and storage, and an external monitoring stack for uptime and error tracking. Each sub-processor is bound by a data processing agreement and is restricted to the minimum data required for its function. Our current sub-processors are PlanetScale (database hosting, EU), Vercel (application hosting), Railway (scan engine hosting) and Resend (transactional email, EU). We notify customers in advance of any addition or change, and you may request the current list in writing at any time from privacy@custodis.app.

6. Your rights

You have the right to access the data we hold about you, to export it in a portable format (CSV or JSON, available directly from the API), to correct anything that is inaccurate, and to delete your account and associated data. Customers in the EU and UK have the rights afforded by GDPR, including the right to lodge a complaint with a supervisory authority. California residents have the rights afforded by CCPA, including the right to know what categories of personal information we collect and the right to deletion. To exercise any right, write to privacy@custodis.app and we will respond within thirty days.

7. Cookies

The product uses only essential cookies: a session cookie, an authentication cookie, and a CSRF token cookie. None of these are used for tracking or advertising. The marketing site sets no analytics cookies without your consent and embeds no third-party tracking pixels, fingerprinting scripts, or social-media widgets. If you decline non-essential cookies, the marketing site continues to function without degradation.

8. Retention

Account data is retained for the active life of the account plus ninety days after closure, after which it is purged from primary storage and rolled out of backups in the next backup cycle. Scan data retention depends on your subscription tier — for paid tiers, rolling twelve months of historical findings and score points is typical, with higher tiers offering longer windows. The audit log is retained for a minimum of twenty-four months regardless of tier, because it is also our record. Specific retention windows are stated in your order form.

9. Children

Custodis is a B2B product directed at security and risk teams. It is not directed at anyone under the age of eighteen, and we do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact privacy@custodis.app and we will delete it.

Questions about your data?

Reach our DPO at privacy@custodis.app.